An attacker can capture and decrypt the communication between the configuration software and the affected devices, since a symmetric encryption algorithm with a fixed key is used to encrypt the...
Dima Kumets explains why he wanted to make his way back to the world of MSP security—and how he ended up as a Principal Product Manager at Huntress.
Targets of spyware attacks in which each malware sample has a limited-scope and a short lifetime include industrial enterprises. Victim organizations’ SMTP services are abused to send phishing...
As more organizations move to the cloud, so do attackers. What can you do to better protect your cloud environment in 2022? Wiz Research has compiled the most pressing cloud security threats and...
What cybersecurity trends will we see in this new year? In this blog, we share some hot takes and predictions for 2022.
Twitch has fallen victim to an anonymous hacker who breached 125GB of data, including the service’s entire source code.
Twitch has fallen victim to an anonymous hacker who breached 125GB of data, including the service’s entire source code.
Community Feature - @SttyKCurated Intelligence's OSINT Ninja - Sh1ttyKids - has shared a collection of geolocation reports related to the REvil ransomware gang. On 14 January, the Russian FSB...
Community Feature - @ZephrFishCurated Intelligence Staff member ZephrFish recently uncovered concerning private information leak in BlackVue vehicular dashcams. Customers of BlackVue dashcams...
Community Feature - @cPeterrCurated Intelligence member Chuong Dong has recently shared his findings in a blog after reverse engineering an emerging ransomware family dubbed Rook. The ransomware...
Huntress is monitoring an incident in which VMware Horizon Servers are being hit with Cobalt Strike. Read our up-to-date blog to learn more.
Read about the exciting new updates to our Ransomware Canaries service.
NCC Group performed a pentest in which they had (notionally) compromised a developer's laptop who could commit code to a certain Java library. The researchers set a pre-requirement file to one...
NCC Group performed a pentest against a web application, in which they leveraged anonymous access to discover a sitemap folder that turned out to be an S3 bucket with directory listing enabled....
We believe it’s time for MSP vendors to level up cybersecurity community efforts, so we’re taking the first step with a $100,000 contribution to DIVD.
Community Feature - @michael_deeboCurated Intelligence member - Michael DeBolt - has expressed his views on what he calls the "CTI long game" and how CTI teams, as a core component of many...
Who is responsible for doing what when a new cloud vulnerability is disclosed? Right now, it can be hard to know.
We recap some of the cybersecurity trends and events in 2021 to prepare for the new year.
Although it is still difficult to say to what extent vulnerable ICS systems are exposed to potential attacks, we hope that, unlike IT infrastructures, most vulnerable OT systems cannot accept...
This is a special joint webcast from the teams of Black Hills Information Security, Wild West Hackin’ Fest, and Active Countermeasures, presented by John Strand. In this webcast, we cover […] The...
Group-IB's recommendations to mitigate this vulnerability and protect your organization.
The MITRE ATT&CK® framework became the industry standard to describe attack tactics and techniques.
The cooperation between Kaspersky and the TÜV Austria Academy focuses on jointly implementing innovative certified training courses for specialists in information technology and industrial...
Behind the scenes of targeted scams
The main challenge with Log4j is understanding your existing infrastructure, and identifying the location of all vulnerable Log4j libraries. Follow Wiz's recommendations to wrap it all before the Holidays!
Read about the NotLegit vulnerability discovered by the Wiz Research Team, where the Azure App Service exposed hundreds of source code repositories.
Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from...
Our partners at United Systems and F1 Solutions talk about their respective journeys with our Managed Microsoft Defender solution.
Here's how to meet the Texas HB 3834 compliance requirement for a cybersecurity awareness training program for all contractors and employees.
We recap our December 2021 episode of Tradecraft Tuesday where we dive into the Log4Shell vulnerability.